CVE-2013-3619

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:supermicro:smt_x9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:sh7758:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:supermicro:smt_x8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:sh7757:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:citrix:netscaler_sdx_firmware:10:*:*:*:*:*:*:*
cpe:2.3:h:citrix:netscaler_sdx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:citrix:netscaler_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:netscaler:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:citrix:netscaler_sd-wan_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:netscaler_sd-wan:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://support.citrix.com/article/CTX216642 - Third Party Advisory () http://support.citrix.com/article/CTX216642 - Third Party Advisory
References () https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities - Third Party Advisory () https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities - Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/89044 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/89044 - Third Party Advisory, VDB Entry
References () https://support.citrix.com/article/CTX216642 - Third Party Advisory () https://support.citrix.com/article/CTX216642 - Third Party Advisory
References () https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf - Vendor Advisory () https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf - Vendor Advisory

Information

Published : 2020-01-02 18:15

Updated : 2024-11-21 01:53


NVD link : CVE-2013-3619

Mitre link : CVE-2013-3619

CVE.ORG link : CVE-2013-3619


JSON object : View

Products Affected

citrix

  • netscaler_sd-wan_firmware
  • netscaler_firmware
  • netscaler_sdx
  • netscaler
  • netscaler_sd-wan
  • netscaler_sdx_firmware

supermicro

  • sh7758
  • smt_x8_firmware
  • smt_x9_firmware
  • sh7757
CWE
CWE-798

Use of Hard-coded Credentials